VYPR

COM for Windows

by Microsoft

CVEs (8)

  • CVE-2018-0824HigKEVMay 9, 2018
    risk 0.78cvss 8.8epss 0.72

    A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server…

  • CVE-2018-8349HigAug 15, 2018
    risk 0.59cvss 8.8epss 0.23

    A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server…

  • CVE-2020-0922HigSep 11, 2020
    risk 0.58cvss 8.8epss 0.05

    A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have…

  • CVE-2026-32162HigApr 14, 2026
    risk 0.55cvss 8.4epss 0.02

    Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.

  • CVE-2020-1507HigSep 11, 2020
    risk 0.52cvss 7.9epss 0.03

    An elevation of privilege vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. To exploit the vulnerability, a user would…

  • CVE-2025-21281HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft COM for Windows Elevation of Privilege Vulnerability

  • CVE-2025-58725HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20806MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.